Home Blog Page 27

Ransomware Attack On Shutterfly Affects Its Network Operations

DeadBolt, Shutterfly ransomware, Cuba ransomware

The U.S.-based photography company Shutterfly confirmed that it had sustained a ransomware attack affecting some of its services, making it the latest victim in the string of ransomware attacks. In an official release, the photography products and image sharing firm stated the cybersecurity incident had affected some of its corporate systems and operations of its Lifetouch, BorrowLenses business, and Groovebook services. However, the attack has not impacted Shutterfly.com, Snapfish, TinyPrints, and Spoonflower sites.

Damage Recovery

Shutterfly stated it had notified the security incident to the law enforcement authorities and engaged third-party cybersecurity experts to investigate the attack. The company also confirmed no impact on customers’ sensitive information.

Also Read: This is How Ransomware Gangs Select their Victims

“As part of our ongoing investigation, we are also assessing the full scope of any data that may have been affected. We do not store credit card, financial account information, or the Social Security numbers of our Shutterfly.com, Snapfish, Lifetouch, TinyPrints, BorrowLenses, or Spoonflower customers, and so none of that information was impacted in this incident. However, understanding the nature of the data that may have been affected is a key priority, and that investigation is ongoing. We will continue to provide updates as appropriate,” the release said.

Conti Ransomware in Suspect!

While threat actors behind the ransomware attack are still unknown, several cybersecurity experts suspect the involvement of the Conti ransomware group. Russia-based Conti group, which is behind several ransomware attacks, is making headlines more often with its double extortion techniques. Recently, the group abused the Log4j flaw (CVE-2021-44228) to gain access to the internal VMware vCenter Server and encrypt vulnerable devices. The Conti is the first to become the sophisticated ransomware group weaponizing Log4j vulnerability.

The Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the FBI alerted users and organizations about the rise of Conti ransomware attacks. To secure organizations’ critical systems against Conti ransomware, the agencies recommended certain security mitigations such as enabling multi-factor authentication,  implementing network segmentation, and keeping operating systems and software up to date.

A Security Reset: How Digital Transformation Leads to Security Transformation

Digital transformation, security transformation

Is there any innovation on the horizon that will help companies stem the onslaught of cyber breaches? Yes, there is. It is called “The Cloud,” not to be feared but to embrace with urgency. The cloud offers enterprises a once-in-a-lifetime opportunity for a security do-over. Executed properly, a move to the cloud offers the opportunity to deliver a level of security unimaginable in the old-world of leaky networks and data centers – and can lead to security transformation.

By Brendan Hannigan, co-founder and CEO, Sonrai Security

Traditional networks and data centers are crammed full of a morass of security products, with each new solution promising questionable benefits and delivering results that daily ransomware headlines and data breaches can measure. Nothing is on the way to change this reality. Gartner predicts that by 2023, 75% of cloud security failures will result from inadequate management of identities, access, and privileges — up from 50% in 2020. The sad fact is that many of these arise not because of sophisticated attacks but rather due to basic misconfiguration. The rapidly expanding suite of cloud providers and their multitude of services with infinite combinations and permutations of settings place an extraordinary burden on enterprise security teams to change.

Data is your most important enterprise asset. The truth is that business data is rarely confined to corporate network perimeters anymore. In the cloud, identities are the security perimeter and must be at the forefront of how you secure your data. Thus, the way to secure enterprise data is to extend enterprise security to your cloud identities (people and non-people).

However, organization after organization use outdated security strategies to protect this number one asset using the outdated network security model. This strategy fails in the public cloud, as we see this in the headlines pretty much weekly over the past three years.

Identities are the new Perimeter

Jay Gazlay, a technical strategist at the Cybersecurity and Infrastructure Security Agency, told members of the National Institute of Standards and Technology’s (NIST) Information Security and Privacy Advisory Board, “Identity is everything now. We can talk about our network defenses, we can talk about the importance of firewalls and network segmentation, but really, identity has become the boundary, and we need to start readdressing our infrastructures in that manner.”

Jay’s assessment is 100% correct and brings to light another hard truth; the network is no longer the perimeter — identities are the new perimeter. Security teams are used to creating boundaries using networks, and placing the security stack where those boundaries meet, and configuring it based on known and locked down data paths. This does not work as a holistic security solution in the cloud. Cloud security teams must think about what identities they control, what are their uses, and what resources they have access to.

Securing identities and data in the cloud is challenging if you use outdated strategy and tooling. Almost like it doesn’t have to be this way.

Security Transformation

The current attack cycle, particularly in the cloud, starts with identity. Attackers seek to access the identity, then pivot between resources, discovering credentials and other people and non-people identities that give them more and more access to get what they want. It’s important to understand that identity extends security beyond the traditional walls of the enterprise, which is why there are failures in applying old network security strategies to the new cloud environment.

But it need not be that way. When properly executed, moving infrastructure and apps to the cloud, hands over the core infrastructure security to the massively funded cloud providers. Unburdened by the struggle of core infrastructure management, networks, and data centers, companies can focus on who and what has access to their data and its protection. Systems enabling deep knowledge and control of corporate data and identities and aligned with corporate policies allow an impressive lockdown of access impossible in old-world data centers.

Still, why are so many so slow to move? Making a wholesale shift to something new creates anxiety, risk, and potential downfall. Companies fear they will lose control when the opposite is true. Executives use security to slow the move to the cloud when in reality, they should be using security as a reason to run – not walk – away from the status quo.

Digital Transformation, executed properly, leads to Security Transformation. Of course, executed poorly, it leads to the status quo. Only when we can make a wholesale mindset shift will our companies, data, identities, and lives be fully secure.


About the Author

Brendan Hannigan is CEO and co-founder of the cloud security software company Sonrai Security. Brendan has spent decades building technologies and businesses in cyber security and networking based on unmet needs. Brendan is a recognized leader in the cybersecurity field, and his perspective spans multiple industry transitions. He’s also an Entrepreneur Partner with Polaris Partners and serves on the board of Flashpoint. At Polaris Partners, Brendan led the investment in cloud-native security company Twistlock and acted as Chairman through its successful sale. Brendan previously was the general manager of the $2 billion IBM Security business. Before this, Brendan was CEO of Q1 Labs, which pioneered the security intelligence and analytics market and built the market-leading QRadar platform. Earlier, Brendan led the network and security practice of Forrester Research and built switching and routing software at Wellfleet Communications and Digital Equipment Corporation. Brendan graduated from University College Dublin with a degree in Computer Science.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.


Want to write for CISO MAG? Read our editorial guidelines. Then send your articles to [email protected]

How Illicit Cryptomining Works, And How to Prevent It

Cryptomining

Whether it’s a surge in value or a decline, cryptocurrencies always make headlines. In addition to price fluctuations, various crypto-related issues such as cryptomining, illegal crypto transfers, or attacks on crypto exchanges are reported more often. The surge of illicit cryptomining continues to be a nightmare for cryptocurrency firms and exchanges. Threat actors are leveraging cryptomining and cryptojacking techniques to infect the targeted systems and mine crypto coins. Here’s how these attacks work and how on can detect them.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

What is Cryptomining?

Cryptocurrency mining or cryptomining is a process of validating cryptocurrency transactions, also called blocks. Cryptocurrencies like Bitcoin, Binance coin, Ethereum, Dash, Monero, etc., use distributed public ledgers to track all the crypto transactions linked to the previous transactions, forming a chain of recorded blocks called a blockchain.

Cryptomining is usually done via sophisticated hardware that solves complex mathematical equations. The first computer (miner) to solve the equation is rewarded with the next block of cryptocurrencies, and the process continues.

How Illicit Cryptomining Works

Anyone with a network of computers (crypto miners) and capable of solving complex mathematical problems can become a crypto miner. However, some crypto miners hire malicious botnets to mine cryptocurrency illicitly. Adversaries leverage malicious cryptomining techniques to compromise cryptocurrencies.  According to Akamai’s report, cybercriminals use several malware variants to infect personal and corporate servers for malicious cryptomining activities. The report stated that the access to fake crypto exchange phishing URLs increased over 500% between March 2020 and May 2021. Threat actors also leverage malicious crypto apps to trick users and steal crypto coins.

Targeting Crypto Wallets

Cryptocurrency hackers often target cryptocurrency exchanges and digital wallets by deploying malicious cryptomining techniques to infect targeted systems and mine crypto coins.

Also Read: How to Safeguard Your Cryptocurrency Wallet from Digital Exploits

A digital wallet (cryptocurrency wallet) allows users to store, transfer, and receive cryptocurrencies without intermediates. Digital wallets are categorized into two types – Hot wallets and Cold wallets. Hot wallets allow users to store, send, and receive digital coins linked with public and private keys that help facilitate transactions. Hot wallets are connected to the internet, making them vulnerable to cyberattacks and unauthorized intrusions. But, cold wallets are stored offline and do not connect to the internet. Therefore, they are not prone to cyberattacks.  Storing your private keys in a cold wallet, also known as a hardware wallet, is the most viable option as these come encrypted, keeping your keys secure.

How to Prevent Illicit Cryptomining  

Cryptocurrency attackers perform illegal cryptomining activities using two methods – Binary-based and Browser-based.

In Binary-based cryptomining, hackers use malicious mobile applications installed on the targeted devices to mine cryptocurrency. These malicious applications automatically download cryptomining botnets to procure digital currency.

In Browser-based mining activity, also known as cryptojacking, bad actors use malicious JavaScript, designed to mine cryptocurrency, embedded into a website. In cryptojacking, threat actors hijack a network of computers and exploit them to mine crypto coins.

How to Prevent Binary-based Cryptomining   

  • Research on the app developers. Visit their official website and find their contact details.
  • Always download apps from an official app store to reduce the risk.
  • Read the terms and conditions carefully. Don’t download if you find anything suspicious.
  • Read the reviews to know more about the app.
  • Read the app permissions. Don’t install if the app asks for more permissions than required.

How to Prevent Browser-based Cryptomining   

  • Frequently update critical systems along with malware intrusion detection software.
  • Implement a BYOD (Bring Your Own Devices) at your company and make security awareness training mandatory for all employees.
  • Use DNS filters, firewalls, and install the best web filtering tools.
  • Install antivirus software and block pages that send cryptojacking mining scripts.
  • Continuously monitor your enterprise’s computing resources, check CPU energy consumption, and ensure no cloud misconfigurations exist.

About the Author:

Rudra Srinivas

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

More from the Rudra.

 

New Malware Discovered With Brazil’s Itaú Unibanco Bank App

MaliciousItaú Unibanco app,Web Application Security, web application attacks

Leveraging counterfeit apps to trick users and deploy malware on the targeted devices is a common attack vector for malware authors. Security experts Cyble recently uncovered a malicious Android application targeting the popular Brazilian banking company Itaú Unibanco. The fake Android app reportedly used a similar icon and name of Itaú Unibanco bank to trick users into downloading it, thinking it was legitimate. The researchers found that the threat actor created a fake Google Play Store page and hosted the malware – sincronizador.apk that targets Itaú Unibanco customers. The app allegedly has over 1,895,897 downloads.

In addition to malware infection, the attackers could also cause damage to users via various cybercriminal activities such as identity thefts, fraudulent financial transactions, etc.

Malicious App details:  

  • ​App Name: _lTAU_SINC/sincronizador
  • ​Package Name: com.app.pacotesinkinstall
  • SHA256 Hash: 3500c50910c94c7f9bc7b39a7b194bac6137cef586281ee22f5439bb2d140480

Infection Chain

Once the user installs the fake application, the website automatically downloads a malicious application with sincronizador.apk from the URL: hxxps://acesso.sincronizadorltoken[.]com/playstore_downloadS34/sincronizador.apk. Whenever the user opens the application, it prompts the user to enable the AccessibilityService and allow permissions to perform other actions such as Observe actions, Retrieve window content, and Perform gestures.

Also Read: How to Spot Malicious or Fake Apps

“Threat Actors constantly adapt their methods to avoid detection and find new ways to target users through increasingly sophisticated techniques. Such malicious applications often masquerade as legitimate applications to trick users into installing them. Users should install applications only after verifying their authenticity and install them exclusively from the official Google Play Store and other trusted portals to avoid such attacks,” the researchers said.              

Mitigation     

The researchers also recommended security measures to prevent malware infections from fake mobile applications. These are:

  • Download and install software only from official app stores like Google Play Store or the iOS App Store.
  • Use a reputed anti-virus and internet security software package on your connected devices, such as PCs, laptops, and mobile devices.
  • Use strong passwords and enforce multi-factor authentication wherever possible.
  • Enable biometric security features such as fingerprint or facial recognition for unlocking the mobile device where possible.
  • Be wary of opening any links received via SMS or emails delivered to your phone.
  • Ensure that Google Play Protect is enabled on Android devices.
  • Be careful while enabling any permissions.
  • Keep your devices, operating systems, and applications updated.

How to Spot Fake Apps

Even with multiple security checks and scans in place, several counterfeit and malicious apps remain undetected and make their way to the Play Store. Here are a few security tips to spot fake and malicious mobile applications:

  • Check for Discrepancies in the App Icon.
  • Observe App and its Developer’s Name.
  • Watch the Download Count.
  • Screenshots and Reviews.
  • App Publish/Update Date and Permissions.

Read our detailed report here

LockBit 2.0, Conti, BlackMatter and Hive Contribute to 60% of Ransomware Attacks

Ransomware Attacks, Graff ransomware attack

Despite constant cybersecurity awareness and law enforcement actions, ransomware operators continue to evolve their hacking techniques to deploy file-encrypting malware, causing damages to targeted critical systems. An analysis from Intel 471 researchers found 612 ransomware attacks attributed to 35 different ransomware variants. Of the attacks, over 60% were tied to four ransomware variants – LockBit 2.0, Conti, BlackMatter and Hive.

“The rise in the ransomware variants Intel 471 has tracked comes as some more notable variants of years past have faded into obscurity. While it’s common practice for ransomware groups to suddenly disappear and re-emerge under a new name, groups’ motives for doing so aren’t well-known. The past few months have been different: we’ve seen several groups go quiet after external actions have forced groups to slow down operations or shut down altogether,” the report said.

According to the report, the most prevalent ransomware variants from July-September 2021 were:

Most Affected Sectors

  • Manufacturing
  • Consumer and industrial products
  • Professional services and consulting
  • Real estate

And the impact on life sciences, health care, financial services, and nonprofit sectors was lesser.

Also Read: Rags to Riches! The Evolution of Ransomware Operators

The Rise of New Ransomware Groups   

The ransomware threat landscape increased rapidly with various ransomware variants and attacks. The NCC group revealed that the number of ransomware attacks reported in November 2021 had increased by 1.9% compared to October 2021. There is a 50% increase in organizations targeted by new ransomware variants like PYSA and LockBit, with a 400% rise in government sector victims.

“Be it due to law enforcement, infighting amongst groups, or people abandoning variants altogether, the RaaS groups dominating the ecosystem at this point in time are completely different than just a few months ago. Yet, even with the shift in the variants, ransomware incidents as a whole are still on the rise,” the report added.

What the Experts Say

Bob DiachenkoSpeaking to CISO MAG about the rise of ransomware attacks, cybersecurity researcher Bob Diachenko said, “Ransomware evolves similarly to any software proposition on the market – there are large groups operating as marketplaces with ransom-as-a-service solutions, state-sponsored APTs, and many independent actors, most of which are simply trying to reach a low-hanging fruit in the form of misconfigured databases.”

How Blockchain Is Shaping Cyber Security and Causing Technology Disruptions for Global Enterprises

blockchain

The Blockchain industry continues to change the lives of not just enterprises but also individuals, helping them lay the foundations of their services and foster future growth. Gartner predicts Blockchain to be one of the top trends for 2020, and by 2025, we will be expecting future technology trends being influenced by its innovations. The public blockchain market holds the highest shares in the global industry with private and hybrid blockchains coming next. 

By Srinivas B, Director and Head of India — Cybersecurity and Blockchain COE 

Investments in Blockchain technology are expected to surpass USD 15.1 billion by 2024, and the technology has been causing massive disruptions throughout different industry verticals. We’ve seen other technology trends making the news, but Blockchain is finally garnering the reputation it deserves.  

According to CoinDesk, over 82% of institutional investors said they would increase spendings on Blockchain and digital assets by 2023. Their reasons for expanding their crypto holdings included the diversification of assets, long-term capital growth, reduced exposure to market volatility, and improved regulatory environments. Blockchain is already being adopted outside the technology industry in healthcare, finance, food safety, and shipping. Supply chain traceability in the gemstone industry is seeing a unique application where the origins of gemstones are uncovered and provide evidence to consumers. Software development companies are making apps for clients, and with the increased use of Blockchain, we can expect the Blockchain market to grow at a CAGR of 69.3% during given forecast periods. 

What is Blockchain? 

Blockchain is a decentralized technology used for doing digital transactions via a distributed ledger. It works as blocks that store financial data about users, with each block being linked in a sequence. In a blockchain model, computational resources are shared among users as nodes connected via a peer-to-peer (P2P) network. As a Distributed Ledger technology, it has various applications and maintains records of cryptocurrency transactions such as Bitcoin, Ethereum, and many others. 

Worldwide Outlook of Blockchain Market 

According to global industry statistics, the blockchain market is forecasted to grow at a CAGR of 79.6% from 2018 to 2023. Industry verticals and players such as large and small SMEs will be the primary adopters of this technology, with Blockchain as a Service (BaaS) driving market growth exponentially in this segment. The rising popularity of blockchain is because of its nature of doing peer-to-peer digital transactions without having intermediaries in between. Data stored in blockchains are reliable, accurate, timely, and readily available. Numerous projects in media and entertainment, healthcare, agriculture, automotive, energy, eCommerce, and retail have benefited from its innovations. 

The COVID-19 pandemic has accelerated digital transformation for many companies, which means there is now an increased interest in digital ledger technology. The global blockchain market can be estimated to be valued at USD 39.7 billion by 2025. At least 25% of the Forbes Global 2000 will be using Blockchain as a foundation technology in their upcoming projects by 2025. 

Future Trends of Blockchain in 2025 

It’s clear that Blockchain will revolutionize all industry verticals and is a technology that can no longer be ignored. By 2025, we can expect to see traditional business models transition entirely to the Cloud and use these distributed ledgers to conduct financial transactions. 

The following is a list of the top future trends of blockchain for 2025 and beyond. 

1. Blockchain as a Service (BaaS)

Blockchain as a service is a new trend that allows businesses to create financial products using distributed ledger technology. BaaS models are cloud-based, and most digital products created using BaaS services do not require any setup, installation, or manual intervention. The introduction of blockchain to social media networking websites will ensure that public data stays secure, giving content creators rightful ownership of their data without letting it fall into the hands of platforms. Microsoft and Amazon are the two leading brands developing BaaS infrastructures and services for businesses. 

BaaS services will foster the creation of decentralized architectures and offer several applications. Cloud vendors are working towards bringing these services within reach of businesses who want to speed up project payments and automatically sign off contracts after their completion. AI and Machine Learning deployments in BaaS models will address bottlenecks faced during the increased adoption of these services. 

2. Interoperability of Blockchain Networks

Blockchain interoperability refers to connecting disparate Blockchains and building an ecosystem where different networks can communicate, sort of like a decentralized exchange center. A use-case of interoperability can transmit data from a Bitcoin block onto another network. 

Interoperable Blockchain blocks and their integration with existing systems will streamline transactions and make it easier to do mass deployments. “Hybrid connectors” is a concept being cited by the industry and is enabling cross-Blockchain communications. Blockchain interoperability is another why cryptocurrency usage is becoming mainstream. Blockchain interoperability benefits include multi-token transactions, improved scalability, data governance, and enhanced connections between various Blockchain networks. 

3. Investments in StableCoins and Logistics 

Blockchain’s reach is expanding by the day and apps are being built using the distributed ledger technology as we speak. Bitcoin is an example of a cryptocurrency that’s volatile by nature in the market. StableCoin is an innovation that’s currently in the works that address this. 2020 is the predicted year when they will experience an all-time high, and we can expect to see an upward trajectory for growth up to 2025 from there.  

The main types of stablecoins in the cryptocurrency market are fiat-backed stablecoins, commodity-backed stablecoins, and crypto-backed stablecoins. Investors will be buying more stablecoins and holding their money for more extended periods as these pose a low risk, offering stable returns on their investments. 

Stablecoins will also serve as the blueprint for real digital currencies meaning buyers won’t have to worry about their values being wiped out overnight, unlike other cryptocurrencies. 

Blockchain is being used to make cryptoasset exchanges and encrypt transactions using public and private keys. Many see Blockchain as a reliable transaction technology for making cryptocurrency transfers and exchanges with other individuals, verify them, and get rewards in the process. 

Blockchain can use its decentralized ledgers to combat the threat of personal identity security leaks and safeguard users. Cybercrime fraud comes in various forms and blocks can be used for encryption critical information such as social security numbers, birth certificates, identity cards, etc. Data silos and a lack of transparency are key challenges faced by the logistics sector and enterprises can leverage Blockchains to solve them by automating processes and validating data sources. 

4. Tokenization

Tokenization is the process of converting a physical asset such as an object, painting, or real estate (anything of value) and representing it as digital coins. Asset tokenization is an emerging trend in the Blockchain world and gaining quite a traction. Converting real-world assets into tokens and helps divide the rights of assets among various owners. Non-fungible tokens will foster digital scarcity and prevent assets from being replicated or copied, which means owners acquire exclusive digital rights to their assets. 

There are many benefits to Blockchain tokenization, such as increased liquidity, lack of third-party involvements, user anonymity, improved immutability, etc. Real-estate tokenization is one of the hottest trends, and many platforms are helping businesses access, exchange, and trade with tokens without compromising on legal compliance. 

5. Revolutionizing Financial Services

The financial industry is one of the early adopters of this technology, and there are many banks, NBFCs, and fintech corps are recognizing its value. Banks are finding that Blockchains help create more secure networks for conducting digital transactions and customers prefer to invest and trade with cryptocurrency. 

A recent report by CB Insights revealed that blockchain-based decentralized ledgers would enable customers to make faster payments, pay lower processing fees, and complete transactions in real-time, a seamless experience. Smart contracts drafted will eliminate third parties and make finances more decentralized in the coming years. Blockchain smart contracts allow parties to execute exchanges when “distributed conditions “are met and streamlines transactions automatically. More than 77% of financial institutions expect to adopt Blockchain technology entirely by 2021, and Gartner predicts that the banking industry will generate up to $1 million through blockchain-based digital transactions during 2021. Digital payments are the future, and there is a possibility that governments will be implementing this technology for effective data governance and management. 

Why Blockchain Trends Are Paving the Way for Companies? 

Immutability is the most significant factor behind increased Blockchain adoption, and since data in chains cannot be corrupted, they are essentially tamper-proof. Supply chain operations are becoming globalized, and that’s another segment where Blockchain trends are emerging. All nodes are linked to a ledger, and when edits are made to a single node, changes done to previous ones get verified and validated. This makes it impossible to alter data without verification, and entities cannot get away with data fraud/theft this way. 

Suppliers, distributors, and clients do not have to interact about every simple transaction, and nodes can update ledgers automatically. The growth of IoT (Internet of Things) is helping the latest Blockchain trends keep up with enterprises and is making data security increasingly sophisticated or complex. The merger of Blockchain and IoT makes machine-to-machine transactions possible, and smart devices can run thanks to their amalgamation autonomously. 

Edge computing is also being combined with Blockchain technology, allowing enterprises to reduce costs, transfer data, and not fall prey to cyber attacks as there are no centralized data repositories. Peer-to-peer Blockchain networks help organizations protect their networks and devices from botnet and DDoS attacks, ensure data privacy & security, and make devices in every network independently secure, which is another driving factor behind the emergence of the latest Blockchain trends.  

Digital companies can take advantage of Blockchain technology and address concerns related to data compliance, privacy, and security by mixing AI and Machine Learning. Blockchain mobile apps are enhancing the P2P transaction experience and verifying cross-border digital payments. Quantum computing is being impacted with the technology as ledgers are used for making data unchangeable and tamper-proof. Complex mathematical equations can be processed instantly for linking public and private keys which makes quantum computers hack-proof and not exploitable. 

The adoption of Blockchain is slowly becoming widespread. In the future, we can expect greater security, more data transparency, and a large volume of financial transactions being processed using this technology. 

References: 

  1. https://lnct.ac.in/future-of-blockchain-technology-by-2025/ 
  2. https://www.globenewswire.com/news-release/2020/06/18/2050049/0/en/Worldwide-Blockchain-Industry-to-2025-Get-In-depth-Insights-on-Your-Competitor-Performance.html 
  3. https://searchcio.techtarget.com/feature/7-must-know-blockchain-trends 
  4. https://www.forbes.com/sites/bernardmarr/2021/03/12/the-six-biggest-blockchain-trends-everyone-should-know-about-in-2021/?sh=1cff4ab36631 

About the Author

Srinivas BalantrapuMr. Srinivas B is a trained multi-dimensional professional with more than 20 years of experience in several fields such as Technology Consulting & Architecting, Product Development, Practice/Project Management/Pre-Sales in AWS, Azure, Google & Oracle Cloud Computing, Blockchain & IoT, and AI/Data Science Technologies. He has gained knowledge in several domains and holds various certifications titles such as Certified Project Management Professional – PMP, Certified Microsoft Azure Solution Architect, Certified Blockchain Solution Architect – CBSA, Certified Blockchain Expert – Blockchain Council, Certified Corda/R3 Developer, Certified IBM Cloud Solution Architect, etc. 

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Ubisoft Suffers Data Breach After Cyberattack

Ubisoft data breach

Ubisoft confirmed a data breach after sustaining a cyberattack. The French video game stated that unknown hackers compromised its IT infrastructure to steal gamers’ personal data. It’s found that threat actors specifically targeted Ubisoft’s popular game series Just Dance.

Information Compromised

Ubisoft clarified that a misconfiguration resulted in unauthorized intrusion. The now fixed misconfiguration enabled the attackers to illicitly access and steal gamers’ personal information. The compromised information included technical identifiers like GamerTags, profile IDs, Device IDs, and Just Dance videos recorded and uploaded to be shared publicly with the in-game community and on your social media profiles.

Also Read: Attention Gamers! Your Cybersecurity Score Matters

“Our investigation has not shown that any Ubisoft account information has been compromised as a result of this incident. Ensuring the privacy of player data is a top priority for Ubisoft, so with full transparency, we wanted to update the community around this incident. All players impacted by this will receive an email shortly and can follow up with our Support team for more info. We have taken all the proactive measures necessary to secure our infrastructure from future incidents, and we thank you for your understanding,” Ubisoft said.

Gamers’ Data on Dark Web!

Trading stolen users’ information on the dark web has become prevalent. Recently, Kaspersky researchers have discovered an advanced Trojan, called the BloodyStealer, sold on darknet forums and used to harvest gamers’ accounts across widely used gaming platforms such as Steam, Epic Games Store, and EA Origin. The Online Gaming industry has become one of the driving forces behind internet penetration to the most remote locations worldwide. Statista, in its global video game market report, projects the industry revenue from the video game market to surpass 138 billion USD by 2021. Given the might of the market, it is a constant favorite of cyberattacks.

Echelon Malware Posted on Cryptocurrency Trading Telegram Channel Targets Crypto Wallets

cryptocurrencies, Echelon Malware

SafeGuard Cyber discovered a sample of the Echelon Malware targeting crypto wallets and user accounts credentials. The researchers detected the malware on a cryptocurrency discussion channel, Telegram.

“Based on the malware and the manner in which it was posted, we believe that is was not part of a coordinated campaign and was simply targeting new or naive users of the channel. The sample of Echelon that we analyzed targets credentials, crypto wallets, and has some fingerprinting capabilities,” SafeGuard said.

The Incident

Researchers at SafeGuard revealed that the attackers exploited the Telegram handle “Smokes Night” to propagate the malware Echelon and steal credentials from user accounts and crypto wallets.

“This was an isolated, one-off incident meant to target new unsuspecting users of the channel. The handle “Smokes Night” was only used once on the channel, and the only post it made was to post Echelon. The post did not appear to be a response to any of the surrounding messages in the channel. We did not see anyone respond to “Smokes Night” or complain about the file, though this does not prove that users of the channel did not get infected,” shared SafeGuard.

Malware Brief

Explaining the malware, the researchers explained that the analysis of the malicious executable actor shows that it contains some anti-analysis features. It has two anti-debugging functions, which immediately terminate the process if a debugger or other malware analysis tools are detected. Additionally, the sample is obfuscated using ConfuserEx v1.0.0.

Also Read: Hackers Steal Cryptocurrency Worth $150 Mn From BitMart Exchange

SafeGuard divulged, “After de-obfuscating the .NET code, we found that the sample performs several crypto wallet and credential-stealing functions, as well as domain detection and computer fingerprinting. The malware will also attempt to take a screenshot of the victim machine.”

Exploited Platforms:

  • Discord
  • Edge
  • FileZilla
  • NordVPN
  • OpenVPN
  • Outlook
  • Pidgin
  • ProtonVPN
  • Psi(Jabber)
  • Telegram
  • TotalCommander

Aimed Digital Currency Wallets:

  • Armory
  • AtomicWallet
  • BitcoinCore
  • ByteCoin
  • DashCore
  • Electrum
  • Exodus
  • Ethereum
  • Jaxx
  • LitecoinCore
  • Monero
  • Zcash

Threat actors continue to prey on the digital platform and leverage every opportunity to cause disruption and assuage their financial greed. Cryptocurrency is now like a trademark to these attacks. Be it the platform or as a medium of ransom exchange, digital currency is a haven for cybercriminals.

Akshat Jain, Co-Founder and CTO, CywareAkshat Jain, CTO of Cyware, opines, “Cryptocurrencies continue to provide a safe haven for cybercriminals and ransomware groups looking to evade being traced. Because these coins are largely anonymous, cybercriminals are heavily relying on these currencies to carry out attacks. As per the data shared earlier this year by the National Cybersecurity Coordinator, India, ​​“by the end of 2021, ransomware is expected to attack a company every 11 seconds and cause damages of up to $20 billion.” The illicit use of cryptocurrency, both to evade sanctions and to obfuscate involvement in criminal activity, will continue to increase in 2022, with ransomware and crypto-jacking being the two most prominent ways that criminals can directly receive cryptocurrency payments from their victims.”

Cryptocurrency exchanges and hot wallets continue to become a primary target for threat actors.  Another victim who joined the bandwagon of crypto hacks was the cryptocurrency trading platform BitMart.

Hackers Exploit Log4j Bug to Attack Belgium Defense Ministry

Log4j Vulnerability, Log4Shell

The ripples of Log4j vulnerability have been reaching various sectors across the globe. Belgium Defense Ministry is the latest victim to join the bandwagon of Log4j flaw victims. According to  a report, the Belgian military confirmed a cyberattack affecting some of its systems connected to the internet. While threat actors behind this attack are unknown, the agency stated they took quarantine measures to restore the affected systems. The attack has been notified to the relevant authorities for further investigation.

Apache Log4j is a Java-based logging utility developed by the Apache Software Foundation. Several companies use the Log4j library worldwide to enable logging and configure a wide set of applications. The Log4j flaw permits hackers to run any code on vulnerable machines or hack into any application directly using the Log4j framework. Looking at its severity, MITRE rated the vulnerability as critical and assigned a CVSS score of 10/10.

Hackers Exploited Log4j Flaw

The report found that unknown hackers exploited the Log4j security vulnerability to penetrate and spy on the military systems. The vulnerability, which emerged recently and was labeled as the most critical flaw ever discovered, poses a significant risk to several governments and corporate networks across the globe. The Log4j flaw allegedly allows an attacker to take control of a vulnerable device,  move around the victim’s network,  and install malware or ransomware.

Ripples of Log4j

Recently, Conti ransomware operators abused the Log4j flaw (CVE-2021-44228) to access the internal VMware vCenter Server and encrypt vulnerable devices. Threat actors targeted specific vulnerable VMware vCenter for lateral movement directly from the compromised network resulting in vCenter access affecting victims in the U.S. and European networks. Conti ransomware became the first sophisticated ransomware group weaponizing Log4j vulnerability.

Glen PendleyCommenting on the rising threats with Log4j vulnerability, Glen Pendley, Deputy  Chief Technology Officer at Tenable, said, “Log4Shell, a critical vulnerability in Apache Log4j, is in a league above every other vulnerability we’ve seen in the last few decades. It gives flaws like Heartbleed and Shellshock, a run for their money because of just how pervasive and devastating it is. Everything across heavy industrial equipment, network servers, down to printers, and even your kid’s Raspberry Pi is potentially affected by this flaw. Some affected systems may be on-premises, others may be hosted in the cloud, but no matter where they are, the flaw is likely to have an impact.

Cybercriminals are already rubbing their hands with glee as early signs of ransomware activity have started to emerge. The worst part is, we aren’t even in the thick of it yet. Don’t be surprised when some major disruptions occur over the next few weeks and months, pointing at Log4j as the root cause.”

Cryptojacking Attacks Rise As Hackers Try to Exploit Linux-based Machines

Cryptojacking

Researchers at Bitdefender Security recently discovered a Romanian-based threat intelligence group hacking Linux machines and targeting systems with weak Secure Shell Protocol (SSH) credentials. The group was using Monero mining software to target cryptocurrency wallets and exploit misconfigurations to cause data breaches. 

By Mukesh Makwana, Lead Blockchain Consultant at MindDeft Technologies

Joseph Carson, Chief Security Scientist and Advisor CISO at Thycotic, said that Linux security had evolved over the years. Unlike before, platforms now offered greater visibility with more outstanding features. Security Linux platforms meant bringing the human element when doing system reconfigurations and managing changes.  

Computer users often used weak credentials, and hackers are going undetected when launching brute force attacks. Hackers were obfuscating Bash scripts using shell script compilers and reporting data back using Discord. In addition to traditional toolkits, they were also using masscan and zmap alongside brute force tools.  

 It’s not uncommon to find Linux users use weak SSH credentials, old usernames, and passwords, and third-party resources make it easier for attackers to take advantage of system vulnerabilities.  

Christoph Hebeisen said cryptojacking was “cloud intensive” and rack up high costs for victims if their risk factors were left unattended. Researchers believe that cryptojacking attacks will rise, and threat actors are supplying their APIs into scripts. Bitdefender Security researchers investigated cryptojacking campaigns and stated that most hackers are untraceable, but despite odds, their digital footprints can often be traced when using these tools. 

The challenge is cracking down on hackers who hide behind stolen code and never use the same tools twice when loading malware. Investigators believe that the methods and techniques employed by adversaries all boil down to whether or not they want to be discovered. Usually, those afraid of being prosecuted due to their country’s laws and regulations tend to keep their tracks hidden and take extra steps for protection. 

How Does This Romanian Cryptojacking Gang Operate? 

The Romanian Cryptojacking Gang uses a ‘Dicot brute force’ technique to spearhead their massive malware campaigns. According to researchers, this is how they operate: 

  • They use a unique scanning method to identify and target Linux servers. 
  • Archives such as tar, Juanito, scn, and skamelot are hosted by them on these servers. 
  • Hackers use toolchains and these archives to find weak SSH credentials and crash them. 
  • They track these unique credentials, connect to SSH, and deploy payloads. 
  • A Go-based Dicot Brute which uses a centralized API server, is then deployed as a service. 
  • Attackers use a hell script compiler and bash scripts for obfuscation. 
  • They use discord and webhooks to cover their tracks and wipe out traces. The goal of their methods is to steal credentials without getting detected. 

Drive-by cryptomining is a scheme where cyber criminals ask for access permissions to users’ cryptocurrency wallets in exchange for offering free content. Malicious programs can mine cryptocurrency in the background even after they leave websites and there are Trojans that can infect Android phones that lead to increased processing power consumption.  

Why Do Brute Force Attacks Work? 

The main reason brute force attacks work is the userbase represented and how these users set weak credentials. Easy to guess and simple passwords are the top reasons why accounts get hijacked through brute force techniques. 

The Dicot Brute Force tool filters out honeypots, and researchers discovered that cryptojacking campaigns are launched using a “.93joshua” loader. 

What is Discord? 

Discord is a VoIP and instant messaging app designed to create communities, do group chats, and share media files in private. It is a free service accessible on both mobile and desktop, being launched to communicate easily with other users while gaming or live streaming. 

Cybercriminals are using Discord to launch DDoS (Distributed Denial of Service) threats since the app involuntarily supports malware distribution through the use of C2 servers and webhooks. Discord was first launched in 2015 and can be linked to Xbox accounts, YouTube, and other social media platforms. 

What is Cryptojacking? 

Crypto hacking refers to hacking into personal and business computer systems to perform cryptomining activities from them. The idea behind cryptojacking is to take advantage of enterprise computing power and resources to siphon cryptocurrency from company wallets and process unauthorized digital transactions without getting detected. 

The malicious code deployed on these systems run in the background, which makes them impossible to detect. And cybercriminals use hijacked computers to do cryptocurrency mining work for them automatically in the process. 

How Cryptojacking Spreads – 3 Main Methods 

There are 3 main ways cryptojacking scripts spread: 

1. File-based Cryptojacking 

This is when a malicious program is executed on the IT infrastructure, corrupting and hijacking systems. File-based cryptojacking is done primarily through emails where users are engaged and made to click on malicious links. When a user clicks on any attachments in these emails, the malicious code downloads and executes itself. The script works in the background and steals information without their knowledge. 

2. Browser-based Cryptojacking

Browser-based cryptojacking scripts refer to instances when a hacker embeds malicious code in a website. A programming language is used to write the script, which is run on user computers, and these are embedded into ads, outdated WordPress plugins, browser extensions, or websites. Supply chain cryptojacking attacks are increasingly becoming more common where hackers compromise JavaScript libraries with malware code. 

3. Cloud Cryptojacking

Hackers search for API keys within the organization to access and exploit Cloud services. When they’re successful in acquiring them, they can use unlimited computing resources to siphon cryptocurrencies and illicitly mine sensitive data while erasing their digital footprints. 

Cryptojacking Prevention Tips 

Cryptojacking is unlike traditional malware invasions, where computers are hijacked and attacked directly to acquire informational assets. In cryptojacking, hackers do not attack computers but exploit them to gain access to CPU processing power. Companies like CoHive author crypto mining scripts and sell them online, which hackers buy and make use of. 

A cryptojacking incident uses significant energy and computing resources, which means it’s a massive drain on an enterprise’s technological bandwidth. An organization that fails to address cryptojacking incidents risks losing money, time and faces reputational hazards. Here are some tips on how to prevent falling victim to cryptojacking attacks for users: 

  • Use browser extensions like MinerBlock or NoCoin to block mining activities online 
  • Patch systems frequently and make sure malware intrusion detection software stays updated. 
  • Implement a BYOD (Bring Your Own Devices) at your company and make security awareness training mandatory for all employees 
  • Use DNS filters, firewalls, and install the best web filtering tools. 
  • Install antivirus software and block pages that send cryptojacking mining scripts 
  • Continuously monitor your enterprise’s computing resources, check CPU energy consumption, and ensure no Cloud misconfigurations exist.

Cryptojacking Consequences Organizations Cannot Ignore 

Here’s a list of the top key reasons why organizations shouldn’t ignore cryptojacking consequences and what they can eventually lead to when left unchecked: 

Network and Device Performance Issues 

Cybercriminals infect computer systems with cryptomining malware which run in the background and automatically mines for coins when users visit websites. In-browser JavaScript scripts and banking malware target CPU processors and cause high workloads on computing performance. CPU overload is a real possibility where the operating system can heat up and crash too. 

Power Drain 

We’ve seen cryptojacking incidents cause massive power drain in network machines. The more machines organizations have, the more dramatically their electricity consumption costs will go up after incidents. 

Misconfigurations in Cloud 

Cyber criminals can exploit vulnerabilities in Cloud platforms and use public cloud environments to mine cryptocurrency 24×7. Misconfigurations in containerization technology and unrestricted Cloud access can spell disaster for employees when cryptojackers take full advantage of these resources. 

Reputational Damages 

Cryptojackers can also make brands fail legal and compliance regulatory requirements by exploiting vulnerabilities and exposing them to the public. Businesses can end up losing client from reputational damages and there is no way of recovering from them. 

What to Do After a Cryptojacking Incident 

Experts advise enterprises to be on the lookout for unexpected network spikes, increased processing power consumption, and intensive resource utilization when scanning for cryptojacking threats. However, if you’ve already been affected the next best step would be to run cyber forensics analysis to analyze the extent of damages incurred. 

Set up real-time malware monitoring solutions and block websites or URLs that are embedded with cryptojacking and communicating with corporate servers. Testing systems for unpatched vulnerabilities, doing vulnerability assessments, and switching to better vendors for hardware/software that aren’t vulnerable to cryptojacking codes are also recommended. Backup/recovery should be the primary focus after an incident and organizations should do their best to secure endpoint devices so that they don’t get compromised again. 

What’s the Cryptojacking Scene? 

China banned cryptocurrency trading exchanges back in 2017, and financial companies were advised not to transact digital coins in Yuan by official authorities. U.S. President Biden stated that the nation had a hand in the Microsoft Exchange email hacks earlier this year, and hackers who worked for the PRC Ministry of State Security (MSS) were involved in recent ransomware, cryptojacking, and extortion schemes all across the world.  

The U.S. Government declared that a ransomware task force was already underway, and authorities were working on cracking down cybercriminals by tracing crypto payments linked to these attacks. Researchers were saying that recent Linux system breaches are a lack of user inattentiveness and server misconfigurations. Several tools are now available to hackers who use malware programs as a Distributed as a Service model. In May, researchers began investigating the cryptojacking group and found that criminals left backdoors that let other adversaries gain access and cause further ramifications such as ransomware attacks. 

Cyber criminals used the Prometei botnet to exploit Microsoft Exchange vulnerabilities in early 2021 and harvested malware to launch state-sponsored attacks. Illicit cryptomining was being done by a cyber threat group dubbed PowerGhost that stole Windows credentials by initiating spear phishing threats on organizations worldwide, according to a cryptocurrency mining threat report 

Carson said that most cryptojacking techniques were shared openly on the dark web. Anyone with access to an Internet connection and crypto mining could start a cryptojacking campaign. A massive risk of cryptojacking is an attack that leads to enormous energy consumption by organizations’ computers. Companies could end up paying thousands of dollars in utilities if they left threats unchecked. 

References: 

1.https://www.livemint.com/market/cryptocurrency/cryptocurrency-prices-today-bitcoin-ether-dogecoin-slip-latest-rates-here-11627870294300.html

2. https://www.iotworldtoday.com/2021/07/12/does-chinas-crackdown-mean-curtains-for-cryptojacking/

3. https://www.financialexpress.com/money/dogecoin-vs-matic-which-is-better-why-doge-is-more-popular-than-polygon-in-india/2301378/

4. https://www.varonis.com/blog/cryptojacking/ 


About the Author 

Mukesh Mukesh Makwana is an experienced lead with over 5 years of experience. His is a skilled professional in Blockchain, Python, ReactJS and Java. He is currently working as a Fullstack Blockchain developer, however he has also worked as a React developer, Python developer and Java Liferay developer in the past. He works on technologies such as Ethereum, Python, Java among others to provide best solutions for the client. Mukesh graduated from Silver Oak University with a Bachelor’s of Engineering (BE) in computer engineering. 

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.